Malicious RTF — malware analysis report

Static analysis result for SHA-256 771f02d96d7eb5b4…

MALICIOUS

RTF

776.0 KB Created: 2017-11-10 20:26:00 First seen: 2018-01-23
MD5: a757b48be9b2574ae630cda47ecdc92e SHA-1: 1796686770be5d32994a615700d261a1efefdf81 SHA-256: 771f02d96d7eb5b4e8b719e3d9848482220a27ca0704c0a156c613348e3a64bd
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002a86.bin rtf-objdata-decoded RTF \objdata at offset 0x2A86 26171 bytes
SHA-256: 2e87c3bf06bcde7020f28cb89c8098ba6927392b1e9602561125b821960a6691
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off000150d5.bin rtf-objdata-decoded RTF \objdata at offset 0x150D5 26171 bytes
SHA-256: 1c8f7f4600c792757cf6d325e6262dd2c97d2a25831c6317beec9a344e9aa037
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00027726.bin rtf-objdata-decoded RTF \objdata at offset 0x27726 26171 bytes
SHA-256: 98db0adf718ac442a5de2db92fee0b1661053fa6505976016f06016b93a9da60
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off00039d77.bin rtf-objdata-decoded RTF \objdata at offset 0x39D77 26171 bytes
SHA-256: 641f7c17276e6a1e5e20ca80ef84d9403f7b0f17c96e44e24851b499a81907a5
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off0004c3c8.bin rtf-objdata-decoded RTF \objdata at offset 0x4C3C8 26171 bytes
SHA-256: f2e133f936751d8b83958e7086fc9433b506e5c38fc35c8319ac58e3c349b260
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off0005ea19.bin rtf-objdata-decoded RTF \objdata at offset 0x5EA19 26171 bytes
SHA-256: 86345a05ad565421df3a7851fe9e250aa6e88af9550515d39c7beb7ac3449d06
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off0007106a.bin rtf-objdata-decoded RTF \objdata at offset 0x7106A 26171 bytes
SHA-256: 8cb9fcf36f9658d73cf316b6376e434813b82ad49704a84106c0bfdb1d812346
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off000836bb.bin rtf-objdata-decoded RTF \objdata at offset 0x836BB 26171 bytes
SHA-256: 9cf2d84b367b0eae2dae33c7833ca229a338eca4a8a7a8ee86ca365ae7b0efcc
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off00095d0c.bin rtf-objdata-decoded RTF \objdata at offset 0x95D0C 26171 bytes
SHA-256: dc6f8ffdb33e9162e8c33454f75e9bc8f143a13da9607b4ceda027ecb6a88662
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000a835d.bin rtf-objdata-decoded RTF \objdata at offset 0xA835D 26171 bytes
SHA-256: 02032e2a9bdc419b4693f5c1fccb4fbb932d3718227dd859cba24fbee740891c
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely